Almost every age and identity verification conversation we walk into starts one step too late. The team has already decided it needs to verify users, and the open questions are all about the vendor: which provider, which flow, how much drop-off, how fast the integration. What nobody has checked is the question underneath all of those, which is whether the law has actually decided the service must verify its users at all, or whether someone assumed it had.
That prior question is the one the Wikimedia Foundation spent a year and a High Court case fighting, and it is worth the attention of anyone running a large general-audience platform. Wikimedia did not go to court over a verification technology. It went to court over a threshold, because under the UK Online Safety Act the label a regulator hangs on your service, not the content you host, is what switches a user identity verification duty on. That is a different kind of compliance risk than the ones we usually write about, and in 2026 it is the one that decides whether the rest of the stack is even required.
What “Category 1” actually switches on
The Online Safety Act sorts regulated services into tiers. The heaviest of them, Category 1, carries duties that the general run of platforms do not have, and the one that matters here is section 64: a provider of a Category 1 service must offer all of its adult users the option to verify their identity, explain in its terms how that verification works, and, per the guidance Ofcom must produce, offer a method that vulnerable adult users can actually use (Online Safety Act 2023, s.64).
Read that carefully, because it is easy to over- or under-state. Section 64 does not order you to verify every user. It orders you to stand up an identity verification capability and put it in front of every adult who wants it, alongside the user-empowerment controls that let people limit their exposure to unverified accounts. It is an offer you are compelled to make, built to a standard, for a population that includes the least technical and most at-risk people on your platform. That is not an age gate. Age assurance asks whether the person is old enough to be here; section 64 asks the platform to know, on request, who its adults actually are. It is an identity control, and it lands on the people who use and post, not on the content they see.
The part that surprises people is what puts you in the tier. The Category 1 threshold conditions are drawn from scale and functionality, not from how risky your content is. A regulated user-to-user service meets them if it has more than 34 million UK monthly active users and runs a content recommender system, or more than 7 million UK monthly users with a recommender system and a feature that lets users easily forward or reshare content (the 2025 threshold regulations). Nowhere in that test is there a word about pornography, gambling, or anything a reasonable person would call harmful. You can host the most wholesome material on the internet and still be Category 1 if you are big enough and you have a feed and a share button.
Why Wikipedia litigated a threshold instead of a vendor
That is precisely why the Wikimedia Foundation, which runs one of the most benign large services in existence, found itself in the Administrative Court. Wikipedia is enormous, it surfaces content algorithmically, and people reshare it constantly, which is exactly the shape the threshold is drawn around. So Wikimedia challenged the categorisation regulations themselves, arguing the thresholds could sweep in a nonprofit encyclopedia whose contributors are volunteers, not a monetized user base.
The Foundation lost that particular challenge. In August 2025 the High Court dismissed its judicial review of the categorisation regulations (Wikimedia Foundation v Secretary of State for Science, Innovation and Technology [2025] EWHC 2086 (Admin)). But the judgment did not hand the outcome to the regulator either. The court held that the regulations were lawful while stressing that Ofcom’s eventual decision to designate a specific service is itself a public-law decision, reviewable by the court, and that if Ofcom wrongly concluded Wikipedia was Category 1 the Foundation would have a remedy by way of judicial review (Herbert Smith Freehills Kramer analysis). As of July 2026 Ofcom has not designated Wikipedia as Category 1, but the Foundation has been told it sits on a watch list and can be reassessed at any time (Wikimedia Foundation). The risk is deferred, not closed.
What Wikimedia was actually defending is worth stating plainly, because it is the real lesson for commercial operators. Its objection was never that identity verification is technically hard. It was that a duty to verify the people behind its accounts turns those identities into something the Foundation has to hold, and a store of contributor identities is a target: for the data breach, for the stalker, for the litigant, and, for editors in authoritarian countries, for a government that would very much like a name to attach to an inconvenient edit. Section 64 is an offer, not a mandate to unmask everyone, but a general-audience platform that builds an identity verification capability has still built a system that collects and, if it is careless, retains identity. Wikipedia fought categorization because being in the tier changes what you are on the hook to build and to keep.
The line moves without you touching your product
Sit with the mechanics of that threshold and the strategic problem becomes clear. Because Category 1 is defined by user counts and features, you can cross into it without shipping anything a product manager would recognize as a change in risk. Grow past 7 million UK users. Add a recommendation feed to lift engagement. Add a reshare button. Any one of those, in the wrong combination, moves the line under your feet, and the identity duty is waiting on the other side. Scope is not a fact you establish once at launch; it is a boundary your own growth and roadmap keep walking you toward.
This is not a UK peculiarity, it is the shape of 2026 regulation everywhere. The EU’s Digital Services Act designates Very Large Online Platforms at 45 million monthly EU users and layers heightened obligations on them for the same reason, that scale itself is treated as risk, which is the backdrop to enforcement actions like the DSA Article 28 minimum-age case against Meta. In the United States the trigger is often content share rather than headcount, but the effect is the same kind of categorical line, whether it is the one-third rule for general-audience platforms or the SCREEN Act’s move away from any content threshold at all. The common thread across all three regimes is that the duty attaches to a classification, and the classification is drawn around what your service is, not only around what it hosts. The first competent question for a compliance team in 2026 is not “which verification vendor,” it is “which category, in which markets, and how close are we to the next line.”
The objection is right; avoidance is the wrong answer
The temptation, reading Wikipedia’s case, is to conclude that the goal is to stay out of scope for as long as possible. That is a reasonable instinct and a bad long-term plan, because the thresholds are designed to catch exactly the platforms that succeed, and because the underlying fear, that verifying users creates a liability, is answerable without dodging the duty. The breach wave that hit age-verification vendors this year proved Wikimedia’s point in the worst way: a stored identity document is not an asset, it is an incident with a delay on it. But the failure in those breaches was retention, not verification. The two are separable.
An identity verification capability that satisfies a duty like section 64 does not have to warehouse anyone. It has to be able to confirm, on request, that a given adult is who they claim to be, and to leave behind proof that the check happened. It does not have to keep the passport scan afterward. Return the verification as a structured decision and an audit trail, discard the source document once the check resolves, and you can offer the control the law requires without building the archive that turns your contributors into a breach headline. For the users who come back, a reusable, cryptographically bound credential lets a verified person re-prove with a lookup instead of a fresh upload, which is both cheaper and less to hold. This is the same discipline we argue for under the banner of verification without surveillance: the deliverable is a defensible decision, not a hoard of evidence. Ofcom’s own steer that the section 64 method has to work for vulnerable adults points in the same direction, toward something accessible and low-friction rather than an intimidating document-upload gauntlet.
Two duties, two operations
A large general-audience platform that lands in Category 1 usually discovers it owes not one verification duty but two, and they are not the same product. The Act’s children’s-access and illegal-content duties are the age side, the “highly effective age assurance” obligations that the corpus has covered at length and that Ofcom is now a year into enforcing. Section 64 is the identity side. Conflate them and you will either over-build, forcing document checks on people who only ever needed an age signal, or under-build, treating an identity duty as if a self-declared birthday satisfied it, which is the mistake the Reddit and ICO episode already showed does not survive contact with a regulator.
The way to keep them straight is the split we build Xident around. A Check is the cheap, fast operation, an order of magnitude below a document scan: a browser-based age signal, a liveness pass, a returning-user lookup. It is what the age-assurance duties want at the point where you are gating access, and it is what keeps drop-off from eating the funnel. A Verification is the heavier operation, a document read and face match against a genuine ID, and it is what an identity duty like section 64 actually calls for. Put each where the law puts it, offer the Verification to the adults who ask and reserve its cost for that surface, and you have answered both duties without paying for the expensive one on every user who only triggered the cheap one. The economics of getting that division right, and of buying it rather than building it, are the whole argument of our build-versus-buy breakdown.
What Xident does here, and what it does not
We are precise about the boundary because scope is exactly the place where a vendor that oversells does real damage. Xident provides the two operations: the age Check for the assurance duties and the identity Verification for a duty like section 64, each returned as a structured decision with an audit trail your compliance and legal systems can cite, and with retention kept to the decision rather than the document. If Category 1 designation lands on you, we can be the accessible, privacy-preserving way you meet the obligation to offer adult users identity verification, without becoming the store of identities that Wikimedia went to court to avoid becoming.
What we do not do is tell you which category you are in. That determination, whether you cross a threshold, in which markets, whether a recommender plus a reshare button tips you over, whether you are on a regulator’s watch list, is a legal and regulatory-scoping question, and it belongs with counsel who can read your user numbers and your feature set against the current regulations and Ofcom’s register. We also do not run the user-empowerment tooling, the transparency reporting, or the content duties that ride alongside section 64 in the same tier; those are separate systems that sit next to identity, not inside it. A vendor who claims to resolve your categorization for you is selling you a comfort that is not theirs to sell.
Wikipedia’s year in court is the clearest signal yet of where the 2026 fight has moved. For most of the last decade the hard question was how to verify. It is becoming whether you have to, because the law increasingly answers that with a label pinned to your size and your shape rather than to your content. Sort the scope question first, with people qualified to answer it, and the verification question stops being a guess. Get them in the wrong order, and you will either build controls the law never asked you for or skip the one it did.